CRITICAL 9.3 CVE-2026-55674 Published 17 Aug 2026

Discourse Color Scheme Cookie XSS Vulnerability

Worried this affects one of your servers?

Discourse, an open-source discussion platform, is affected by an arbitrary HTML injection vulnerability that can lead to JavaScript execution.

Before versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id or dark_scheme_id cookie to inject arbitrary HTML into a Discourse page. The cookie value was rendered into a color scheme tag without escaping, allowing the attacker to break out of the attribute and inject a tag that bypassed Discourse's nonce-based Content Security Policy.

  • Affected: versions prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0
  • Impact: arbitrary JavaScript execution in visitors' browsers
  • Fixed: versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

Reference: CVE-2026-55674 on NVD

← Back to Security News